Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium
A company requires all its employees to use a combination of a password and a one-time code generated by a mobile application to access internal systems. This measure is implemented to ensure that even if a password is stolen, unauthorized access is still prevented. Which security concept is the company enforcing?
- AMulti-factor authentication (MFA)
- BAuthorization
- CSingle Sign-On (SSO)
- DNon-repudiation
Show answer & explanationAnswer & explanation
Correct answer: A. Multi-factor authentication (MFA)
Multi-factor authentication (MFA) requires users to provide two or more verification factors to gain access to a resource. In this scenario, the 'password' represents 'something you know,' and the 'one-time code generated by a mobile application' represents 'something you have,' fulfilling the MFA requirement.
Why the other options are wrong
- B. Authorization determines what an authenticated user can do, not how they prove their identity.
- C. SSO allows a user to log in once to access multiple applications, simplifying login, but not primarily enhancing the authentication strength itself in this manner.
- D. Non-repudiation ensures that a party cannot deny having performed an action, which is not the primary goal here.
Multi-factor Authentication (MFA)
A security system that requires a user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.
- Combines different types of authentication factors.
- Common factors: something you know, something you have, something you are.
- Significantly reduces the risk of unauthorized access.
Memory trick: Authentication factors are how you prove you are who you say you are.